Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Edit/Modify Non-Sensitive Information IDOR should be categorzed as P4 #406

Closed
georgedevasia0 opened this issue Feb 16, 2024 · 2 comments
Closed

Comments

@georgedevasia0
Copy link

As of now Edit/Modify Non-Sensitive Information IDOR is categorized as P5. Suppose I am editing a cross tenant record where I don't have the access, it is medium critical and it should have a higher severity.

If I'm editing/modifying a iterate Non-Sensitive Information, then the impact is much higher than we imagine. As per the vulnerability rating taxonomy, all IDOR's except Read Non-Sensitive Information should be having minimum priority of P4.

Please try to do immediate changes in the classification.

@TimmyBugcrowd
Copy link
Contributor

Thank you for your participation. We will soon make changes for the IDOR section and I will update you here and get your input as well.

@TimmyBugcrowd
Copy link
Contributor

Hi,

After an internal discussion, this is what we came up in order to update the IDOR's:
#435

We're going to try this approach for some time and see what happens.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

2 participants